
import pyshark
import re
from Behinder import *

b64re=re.compile(r"^[\w\+/]+={0,2}$")


cap=pyshark.FileCapture("webshell.pcapng", display_filter="http.content_length")
tmp=[]
for c in cap:
    for i in c:
        try:
            re11=re.search(b64re,i.file_data)[0]
            print(re11)
            tmp.append(i.file_data)
        except:
            continue

#print(tmp)
decrypter = JAVA(key='09020dd54a897ba0')
for i in tmp:
    try:
        data = decrypter.decrypt_req_payload(i.encode())
        print(data.decode("utf-8","ignore"))
        #print(data)
    except:

        continue